dkim=temperror and spf=temperror

Discussion in 'ISPConfig 3 Priority Support' started by Alessio calvio, Feb 8, 2021.

  1. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    hello I downloaded an image of a VM ispconfig https://www.howtoforge.com/perfect-...fig-3-1/#-install-amavisdnew-spamassassin-and -clamav Configured everything and it seems to receive and send mail correctly. However, I get many incoming mails with a SPAM tag despite the fact that the receiving domain is set level uncensored. this is what throne in the headers

    X-Spamd-Bar: ++++
    X-Spam-Level: ****
    Authentication-Results: ******mail.study****.it;
    dkim=temperror header.d=libero.it;
    spf=temperror smtp.mailfrom=studio*****[email protected]

    DNS IS OK
    mail:~# ping www.libero.it
    PING d31d9gezsyt1z8.cloudfront.net (65.9.58.126) 56(84) bytes of data.
    64 bytes from 65.9.58.126 (65.9.58.126): icmp_seq=1 ttl=242 time=5.13 ms
    64 bytes from 65.9.58.126 (65.9.58.126): icmp_seq=2 ttl=242 time=5.13 ms

    thanks for help
    alessio
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Check which rule you have chosen in the mailbox itself. mailbox rules override the domain-wide rule.
     
  3. till

    till Super Moderator Staff Member ISPConfig Developer

    And to find out why you get such a high score, take a look at the mail headers, the affected rules are listed there.
     
  4. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    Hello Till all mailbox SPAM settings are: inhreit domain settings.

    And this is a example to analyze:

    Return-Path: <studio*****@libero.it>
    Delivered-To: claudio.*****@studiolegale******.it
    Received: from saturno*****.studydata.it
    by saturno****.studydata.it with LMTP
    id ju1dJnYQIWD+WwAAJHe8+g
    (envelope-from <studio*****@libero.it>)
    for <claudio.*****@studiolegale******.it>; Mon, 08 Feb 2021 11:20:38 +0100
    Received: from libero.it (smtp-35-i2.italiaonline.it [213.209.12.35])
    by saturno*****.studydata.it (Postfix) with ESMTPS id 82E8419C1338
    for <claudio.*****@studiolegale******.it>; Mon, 8 Feb 2021 11:20:30 +0100 (CET)
    Received: from oxapps-31-138.iol.local ([10.101.8.184])
    by smtp-35.iol.local with ESMTPA
    id 93eflocddYYaL93eflny2E; Mon, 08 Feb 2021 11:20:29 +0100
    x-libjamoibt: 1601
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=libero.it; s=s2014;
    t=1612779630; bh=2Kth9JGXctAsoI64JMS0zw7D5xmqbOIyHlkV8CFjZjY=;
    h=From;
    b=M3QyilEbsJXcHdq7+7TsNjdbPwkHJuYKGVdw7g9uso4rTu4jmJehdLoJPlKtBjHkC
    ixTVmteNe2R3lIe3XJdR2B3Xzx4joBQk0gEgX/+FW6bt6Uh1W6CJGTntQNxJWBidW6
    w6XbTfsWbJ8XW0NWX2/PGnQOIP2xiGOWSKxqOUnlLX1UCIJWhCZOx3QOoNEV/mOGtl
    FLR+qZ9FBHuQhq6tjQuTN1hoYRp9pu2WYO23LYBZDpcY31N0y80lvtJHByjX/gK9n/
    VeLNHJqCO/KncFeYsBnPscIl+jlasvzL1AZ8YbEXnNlWEvnenaPA6bxCBpFXqgpO1O
    V7IRTLMuCgd4Q==
    X-CNFS-Analysis: v=2.4 cv=Jbt5EWGV c=1 sm=1 tr=0 ts=6021106e cx=a_exe
    a=SkAuTGSu9wVn7tcq8ZjrZA==:117 a=i-dgTvOvYrEA:10 a=Pc1lvqftYBMA:10
    a=41a6zXJvAAAA:8 a=PjHqXa0ZAAAA:8 a=mD_Oj0B1AAAA:8 a=Q8QIzaNw0gjC1O6ir7UA:9
    a=QEXdDO2ut3YA:10 a=MI25DDl_9_oA:10 a=e9wIQF-uHKwA:10 a=N95lg1s3AAAA:8
    a=_SYInOMhAAAA:8 a=dvoI8TJr5JbPJwrKXF8A:9 a=QlazaDTd-MWjt5hL:21
    a=_W_S_7VecoQA:10 a=NWVoK91CQyQA:10 a=q0YS8JLpTcR1FmbdfFkq:22
    a=2oo-fKB4JA_PVTEXHNDT:22 a=Kbwbov9la9FR0KH0iMZO:22 a=M4HizKAwcfzBr8KOGiYm:22
    a=JLb2ESviCWC9AerJ8HPF:22
    Date: Mon, 8 Feb 2021 11:20:29 +0100 (CET)
    From: studio*****@libero.it
    To: "claudio.*****@studiolegale******.it"
    <claudio.*****@studiolegale******.it>
    Message-ID: <[email protected]>
    In-Reply-To: <[email protected]>
    References: <[email protected]>
    Subject: Fwd: Conferma
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary="----=_Part_109057_922387670.1612779629873"
    X-Priority: 3
    Importance: Normal
    X-Mailer: Open-Xchange Mailer v7.10.3-Rev27
    X-Originating-IP: 151.33.2.189
    X-Originating-Client: open-xchange-appsuite
    x-libjamsun: Wu3xE2EYgsT6ML4fafbq1wtS6vebPMi+
    x-libjamv: UmdBWavCgYY=
    X-CMAE-Envelope: MS4xfOrsqQ5UeMAj/AnQFJpFnN6gyDWJdj/GJyT0vNu8kbhisqlfSFNXu+WQDr3d450bWygTSGyr7gLhGmEy7SrE2zEKccsaOJtMPfH6azKVv5mot30Aiq35
    vHq/libzmMHG4J6YhSnj+It+FxQMkGVFRjY6mWWf6tGWxHG2JEji/7atpqBCuCZ+lshfpTLFRNRzzc/t9RtaOyXVb9U4qIqwtYD+LirtyeVgbrWDKuIfR5+y
    X-Spamd-Bar: ++++
    X-Spam-Level: ****
    Authentication-Results: saturno*****.studydata.it;
    dkim=temperror header.d=libero.it;
    spf=temperror smtp.mailfrom=studio*****@libero.it
     
  5. Jesse Norell

    Jesse Norell ISPConfig Developer Staff Member ISPConfig Developer

    You said you downloaded an image with amavis/spam assassin, but your mail headers look like you're using rspamd, so be sure to check/set the rspamd settings in your Uncensored spam filter policy.
     
  6. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    yep see now and i use rspamd.
    perfect but why uncensored not work and how to identify this error dkim=temperror

    now I started reading the rspamd doc to understand how it works. inexplicably I have amavis-new running, maybe it just checks for viruses.
     
  7. till

    till Super Moderator Staff Member ISPConfig Developer

    The vm image does not ship with rspamd, so you must have installed it manually afterwards. please check postfix main.cf, what do you find in the content_filter line?
     
  8. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    hello no line content_filter in main.cf
    /etc/postfix# find ./ -type f | xargs grep filter
    ./postfix-files:$manpage_directory/man8/postfix-add-filter.8.gz:f:root:-:644
    ./master.cf: -o content_filter=
    ./master.cf: -o content_filter=
    ./master.cf_bck: -o content_filter=
    ./master.cf_bck: -o content_filter=
    look

    :/etc/postfix# ps auxf | grep spam
    root 24351 0.0 0.0 6096 816 pts/0 S+ 17:54 0:00 \_ grep spam
    _rspamd 5959 0.0 0.3 137404 59808 ? Ss feb08 0:00 rspamd: main process
    _rspamd 5978 0.0 0.3 228796 58532 ? S feb08 0:04 \_ rspamd: rspamd_proxy process (localhost:11332)
    _rspamd 5979 0.0 0.3 151940 58868 ? S feb08 0:05 \_ rspamd: controller process (localhost:11334)
    _rspamd 5980 0.0 0.4 196296 71244 ? SL feb08 0:04 \_ rspamd: normal process (localhost:11333)

    rspamd running!!!

    i think i made a mistake during installation. you have a link to check the integration status between postfix and rspamd
     
  9. till

    till Super Moderator Staff Member ISPConfig Developer

    Ok, that#s good so far as content_filter is used by amavis only and it must be empty or not present on Rspamd systems.
     
  10. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    Hi till, server run rspamd.
    too many emails are tagged as spam despite the domain and the accounts are set as uncensored policy.
    in the header of the emails I still find

    this is an example:
    X-Spamd-Bar: ++++++++
    X-Spam-Level: ********
    Authentication-Results: saturnomail.studydata.it;
    dkim=temperror header.d=amazon.it;
    dkim=temperror header.d=amazonses.com;
    spf=temperror smtp.mailfr[email protected]bounces.amazon.it
     
  11. Th0m

    Th0m ISPConfig Developer Staff Member ISPConfig Developer

    It seems there are missing some headers from this email. Please share the full headers.
     
  12. Jesse Norell

    Jesse Norell ISPConfig Developer Staff Member ISPConfig Developer

    Change your Uncensored policy settings if you don't want the headers; there isn't currently a way to actually disable scanning, you simply set high thresholds. I think you'll still have the authenticated-results header, which should not cause any issues.
     
  13. Jesse Norell

    Jesse Norell ISPConfig Developer Staff Member ISPConfig Developer

    Actually the bar/level may always be added (and soon X-Spam-Status), it's the X-Spam header which is added at the tag threshold. If you don't have 'X-Spam: Yes' showing up, the message is not marked as spam.
     
  14. Alessio calvio

    Alessio calvio New Member HowtoForge Supporter

    hello although I still have the problem if I reactivate the filter, now it seems that I managed at least to disable it.
    I will investigate later by reactivating one account at a time and analyzing the behavior of rspamd.
    for the sake of completeness, I report the current status of the headers:
    Return-Path: <[email protected]>
    Delivered-To: [email protected]+++++.org
    Received: from saturno++++.study++ta.it
    by saturno++++.studydata.it with LMTP
    id EGIPKbpbM2ADMgAAJHe8+g
    (envelope-from <[email protected]>)
    for <[email protected]+++++.org>; Mon, 22 Feb 2021 08:22:34 +0100
    Received: from ynet.cloud.host15.chaser-deals.com (ynet.cloud.host15.chaser-deals.com [185.31.66.196])
    by saturno++++.stud++ata.it (Postfix) with ESMTPS id 89BE519C115E
    for <[email protected]+++++.org>; Mon, 22 Feb 2021 08:22:34 +0100 (CET)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=dkim; d=chaser-deals.com;
    h=Message-ID:Date:Subject:From:Reply-To:To:MIME-Version:Content-Type:
    List-Unsubscribe:List-Id; [email protected];
    bh=sxvdf/QkDhXg4qVgsEFB1mpvfMDVV/t3rjwW2JEzbHY=;
    b=Sy7bekB9uiOGrJ4364SQL8Kwg/65FJSGbBGBIID5mWn1XpNCKVHJSwDUzbqek+qsI6ev2gVrmXzw
    v3nrkre0aHEbWAXYozfaeqVnpIUkEnJ2WQmrcyGR5lWrPv2GbyJsqNjkVi57MCCb93088zc7IX1S
    cqTFBqS6n7RO8mqmk3E=
    DKIM-Signature: v=1; a=rsa-sha256;
    bh=sxvdf/QkDhXg4qVgsEFB1mpvfMDVV/t3rjwW2JEzbHY=; d=chaser-deals.com;
    h=Message-ID: Date: Subject: From: Reply-To: To: MIME-Version: Content-Type:
    Precedence: List-Unsubscribe-Post: List-Unsubscribe: List-Id: Feedback-ID;
    [email protected]; s=mailer; c=relaxed/relaxed; t=1613978495;
    b=I+fsd9S1fJaz8R0OdTycwvDMxavRnRPfeoYAYJLzVGXrOEIKpm/tImC/+JeIEmVhqvQVTfeIl
    yqNDNvNhkjSWlZYRvF+TixQLknnK8DPE9+InyIpjK9ThuyuxYMKxalVken7dl2iO4kvXvNyPs
    IlkDIs9cmWuwf41hrdm88XK0L/nlgSyalcDhbZ5BZQs+MYg9mT1QQsujIQMtfFqQwkCtY/5eq
    WD4ar2vgDBwzpnpkgz0b6B90eZ1DWA4HeeZkTeWwV9xw6v5KsSDzxjVPELJYEO12w5+Vd2fRR
    G/u2YBUtwNb8sAGdHklz3Xde5hZOMXDZcClcPtvO3iE2hpNJTg==
    Message-ID: <[email protected]>
    Date: Mon, 22 Feb 2021 07:21:35 +0000
    Subject: Gli sconti d'inverno Bottega Verde continuano! Tutto a partire da
    =?utf-8?Q?1=E2=82=AC?= + consegna gratis!
    From: Bottega Verde via tariffe comparate <[email protected]>
    Reply-To: Bottega Verde via tariffe comparate <[email protected]>
    To: "[email protected]+++++org" <[email protected]+++++.org>
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary="_=_swift_v4_1613978495_dec89a265dd6eaffbcc6245311c63935_=_"
    X-Report-Abuse: Please report abuse for this campaign here:
    https://tracking.chaser-deals.com/campaigns/pw431k1zstcbd/report-abuse/pl839ayjbmd4b/xf934se8kofb5
    X-OFS-Tracking-Did: 14
    X-OFS-Subscriber-Uid: xf934se8kofb5
    X-OFS-EBS: https://tracking.chaser-deals.com/lists/block-address
    X-OFS-Delivery-Sid: 262
    X-OFS-Customer-Uid: rp552nflpv399
    X-OFS-Customer-Gid: 1
    X-OFS-Campaign-Uid: pw431k1zstcbd
    X-Mailer: Ofscorn
    Precedence: bulk
    List-Unsubscribe-Post: List-Unsubscribe=One-Click
    List-Unsubscribe: <https://tracking.chaser-deals.com/l...zstcbd?source=email-client-unsubscribe-button>,
    <mailto:[email protected]?subject=Campaign-Uid:pw431k1zstcbd /
    Subscriber-Uid:xf934se8kofb5 - Unsubscribe request&body=Please unsubscribe
    me!>
    List-Id: pl839ayjbmd4b <Gestione della lista>
    Feedback-ID: pw431k1zstcbd:xf934se8kofb5:pl839ayjbmd4b:rp552nflpv399
    Authentication-Results: saturno++++++.studydata.it
    X-Spamd-Bar: /
     

Share This Page